Open Redirect Vulnerability in WPO365 | Microsoft 365 Graph Mailer Plugin
CVE-2025-1488
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 February 2025
What is CVE-2025-1488?
The WPO365 | Microsoft 365 Graph Mailer plugin for WordPress is susceptible to an Open Redirect vulnerability across all versions up to and including 3.2. This issue arises from inadequate validation of the redirect URL provided via the 'redirect_to' parameter. As a result, unauthenticated attackers may exploit this flaw to redirect unsuspecting users to malicious websites if they can deceive them into performing a certain action. This is particularly concerning when the plugin is active but not properly configured, leaving users exposed to potential phishing attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPO365 | MICROSOFT 365 GRAPH MAILER * <= 3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved